
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab to ship better, more secure software faster.
An Overview of This Role
GitLab's Security Risk function is responsible for reducing risk across the security division: third-party risk (TPRM), annual security risk assessments, quarterly risk reporting, and remediation of security findings. As a Senior Security Risk Engineer, you'll take ownership of risk identification, quantification, and remediation tracking across the business, driving automation and modernization using AI and scripting.
Reporting to the Security Risk Manager, you will partner closely with Security, Legal, IT, Product, and Engineering to translate technical findings and vendor risk into business-relevant risk statements and treatments.
What You'll Do
- Own risk identification, analysis, and prioritization across third-party risk (TPRM), security risk assessments, and security findings using established frameworks (e.g., NIST RMF, ISO 31000, NIST 800-39).
- Translate technical vulnerabilities, control gaps, and risk findings into clear, quantified risk statements that non-security stakeholders and leadership can act on.
- Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal, and escalating stalled or high-severity items.
- Mature and maintain a risk register and quarterly reporting cadence giving leadership visibility into open risk and remediation progress.
- Own and mature AI risk management, including AI impact assessments and risk treatments, to support ISO 42001 certification.
- Design, develop, and implement key risk indicators and supporting metrics for top risks.
- Identify manual, repetitive steps in risk and TPRM workflows and build automation, scripting, or AI-enabled tooling to remove them.
- Monitor the internal and external risk landscape to identify and escalate emerging risks before they become findings.
What You'll Bring
- 5+ years of experience in security risk management, working with security-centric risk management or compliance frameworks (e.g., NIST RMF, NIST 800-39, ISO 31000).
- Familiarity with AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
- Experience designing and executing qualitative and quantitative risk analyses.
- A track record of driving risk assessments, risk registers, and remediation efforts to closure across cross-functional environments.
- Demonstrated bias toward automation: personally built scripts, workflows, or AI-enabled tooling that reduced manual risk or GRC work.
- Comfort operating with ambiguity, managing multiple concurrent assessments, and reprioritizing under tight deadlines.
- Exceptional written and verbal communication skills with the ability to translate security risks into business risks.
- Strong understanding of cloud security, SaaS security models, and DevSecOps practices.
- Relevant certifications (e.g., CISSP, CISM, CISA, CRISC) are preferred.
About the Team
The Security Assurance organization helps GitLab build and maintain trust by strengthening security, compliance, and risk across the company. The Security Risk team owns third-party risk, security risk assessments, and remediation of security findings, collaborating closely with Security Compliance, Security Governance, and Security Enablement.
Timezone overlap
UTC-8β-4
Culture
Async-friendly
Benefits
Health, Unlimited PTO, Equity, ESPP, Parental leave, Learning, Commission, PTO, Wellness
Open to
NA
Sign in to track applications and earn points.